VulnSea

Tagged “pip”

CVEs tagged pip, newest first.

4637 CVEsRSS

CVE-2026-34450Medium
6mo ago

Claude SDK for Python has Insecure Default File Permissions in Local Filesystem Memory Tool

Claude SDK for Python has Insecure Default File Permissions in Local Filesystem Memory Tool

▾ Sunlitanthropic · anthropicEPSS 0.17%via OSV
CVE-2026-34515Medium
6mo ago

AIOHTTP affected by UNC SSRF/NTLMv2 Credential Theft/Local File Read in static resource handler on Windows

AIOHTTP affected by UNC SSRF/NTLMv2 Credential Theft/Local File Read in static resource handler on Windows

▾ Sunlitaiohttp · aiohttpEPSS 0.50%via OSV
CVE-2026-34519Low
6mo ago

AIOHTTP has HTTP response splitting via \r in reason phrase

AIOHTTP has HTTP response splitting via \r in reason phrase

▾ Sunlitaiohttp · aiohttpEPSS 0.40%via OSV
CVE-2026-34516High· 7.5
6mo ago

AIOHTTP has a Multipart Header Size Bypass

AIOHTTP has a Multipart Header Size Bypass

▾ Twilightaiohttp · aiohttpEPSS 0.61%via OSV
CVE-2026-34730Medium· 5.5
6mo ago

Copier `_external_data` allows path traversal and absolute-path local file read without unsafe mode

Copier `_external_data` allows path traversal and absolute-path local file read without unsafe mode

▾ Sunlitcopier · copierEPSS 0.21%via OSV
CVE-2026-34513Low
6mo ago

AIOHTTP Affected by Denial of Service (DoS) via Unbounded DNS Cache in TCPConnector

AIOHTTP Affected by Denial of Service (DoS) via Unbounded DNS Cache in TCPConnector

▾ Sunlitaiohttp · aiohttpEPSS 0.61%via OSV
CVE-2026-34446Medium· 4.7
6mo ago

ONNX: Arbitrary File Read via ExternalData Hardlink Bypass in ONNX load

ONNX: Arbitrary File Read via ExternalData Hardlink Bypass in ONNX load

▾ Sunlitonnx · onnxEPSS 0.17%via OSV
CVE-2026-34525Medium
6mo ago

AIOHTTP accepts duplicate Host headers

AIOHTTP accepts duplicate Host headers

▾ Sunlitaiohttp · aiohttpEPSS 0.39%via OSV
CVE-2026-34518Medium· 5.3
6mo ago

AIOHTTP leaks Cookie and Proxy-Authorization headers on cross-origin redirect

AIOHTTP leaks Cookie and Proxy-Authorization headers on cross-origin redirect

▾ Sunlitaiohttp · aiohttpEPSS 0.40%via OSV
CVE-2026-34939Medium· 6.5
6mo ago

PraisonAI Has ReDoS via Unvalidated User-Controlled Regex in MCPToolIndex.search_tools()

PraisonAI Has ReDoS via Unvalidated User-Controlled Regex in MCPToolIndex.search_tools()

▾ Sunlitpraisonai · praisonaiEPSS 0.45%via OSV
CVE-2026-34726Medium· 4.4
6mo ago

Copier `_subdirectory` allows template root escape via parent-directory traversal

Copier `_subdirectory` allows template root escape via parent-directory traversal

▾ Sunlitcopier · copierEPSS 0.37%via OSV
CVE-2026-34222High· 7.7
6mo ago

Open WebUI has Broken Access Control in Tool Valves

Open WebUI has Broken Access Control in Tool Valves

▾ Twilightopen-webui · open-webuiEPSS 0.46%via OSV
CVE-2026-34520Critical· 9.1
6mo ago

AIOHTTP's C parser (llhttp) accepts null bytes and control characters in response header values - header injection/security bypass

AIOHTTP's C parser (llhttp) accepts null bytes and control characters in response header values - header injection/security bypass

▾ Midnightaiohttp · aiohttpEPSS 0.68%via OSV
CVE-2026-34445High· 8.6
6mo ago

ONNX: Malicious ONNX models can crash servers by exploiting unprotected object settings.

ONNX: Malicious ONNX models can crash servers by exploiting unprotected object settings.

▾ Twilightonnx · onnxEPSS 0.51%via OSV
CVE-2026-34954High· 8.6
6mo ago

PraisonAI Has SSRF in FileTools.download_file() via Unvalidated URL

PraisonAI Has SSRF in FileTools.download_file() via Unvalidated URL

▾ Twilightpraisonaiagents · praisonaiagentsEPSS 0.41%via OSV
CVE-2026-34517Low
6mo ago

AIOHTTP has late size enforcement for non-file multipart fields causes memory DoS

AIOHTTP has late size enforcement for non-file multipart fields causes memory DoS

▾ Sunlitaiohttp · aiohttpEPSS 0.51%via OSV
CVE-2026-34514Low
6mo ago

AIOHTTP has CRLF injection through multipart part content type header construction

AIOHTTP has CRLF injection through multipart part content type header construction

▾ Sunlitaiohttp · aiohttpEPSS 0.40%via OSV
CVE-2026-34591Medium· 6.5
6mo ago

Poetry Has Wheel Path Traversal Which Can Lead to Arbitrary File Write

Poetry Has Wheel Path Traversal Which Can Lead to Arbitrary File Write

▾ Sunlitpoetry · poetryEPSS 0.55%via OSV
CVE-2026-74874Medium
6mo ago

openssl-encrypt has non-cryptographic PRNG used for steganography pixel selection

openssl-encrypt has non-cryptographic PRNG used for steganography pixel selection

▾ Sunlitopenssl-encrypt · openssl-encryptEPSS 0.44%via OSV
CVE-2026-74872Medium
6mo ago

openssl-encrypt: Dynamic .so loading for Whirlpool uses broad glob pattern without integrity verification

openssl-encrypt: Dynamic .so loading for Whirlpool uses broad glob pattern without integrity verification

▾ Sunlitopenssl-encrypt · openssl-encryptEPSS 0.68%via OSV
CVE-2026-74878Critical
6mo ago

openssl-encrypt: TOTP rate limiter is in-memory only — not shared across workers, lost on restart

openssl-encrypt: TOTP rate limiter is in-memory only — not shared across workers, lost on restart

▾ Midnightopenssl-encrypt · openssl-encryptEPSS 0.75%via OSV
CVE-2026-74873Medium
6mo ago

openssl-encrypt has visible password in process list via --password CLI argument

openssl-encrypt has visible password in process list via --password CLI argument

▾ Sunlitopenssl-encrypt · openssl-encryptEPSS 0.32%via OSV
CVE-2026-74875Medium
6mo ago

openssl-encrypt silently skips schema validation when jsonschema library is not installed

openssl-encrypt silently skips schema validation when jsonschema library is not installed

▾ Sunlitopenssl-encrypt · openssl-encryptEPSS 0.27%via OSV
CVE-2026-34203Low· 2.7
6mo ago

Nautobot: Management of users via REST API does not apply configured password validators

Nautobot: Management of users via REST API does not apply configured password validators

▾ Sunlitnautobot · nautobotEPSS 0.34%via OSV
CVE-2026-32794Medium· 4.8PoC
6mo ago

Apache Airflow Provider for Databricks: TLS Certificate Verification is Disabled in Databricks Provider K8s Token Exchange

Apache Airflow Provider for Databricks: TLS Certificate Verification is Disabled in Databricks Provider K8s Token Exchange

▾ Twilightapache-airflow · apache-airflowEPSS 0.43%via OSV
CVE-2026-32716High· 8.1
6mo ago

SciTokens has an Authorization Bypass via Incorrect Scope Path Prefix Checking

SciTokens has an Authorization Bypass via Incorrect Scope Path Prefix Checking

▾ Twilightscitokens · scitokensEPSS 0.43%via OSV
CVE-2026-27124High
6mo ago

FastMCP: Missing Consent Verification in OAuth Proxy Callback Facilitates Confused Deputy Vulnerabilities

FastMCP: Missing Consent Verification in OAuth Proxy Callback Facilitates Confused Deputy Vulnerabilities

▾ Twilightfastmcp · fastmcpEPSS 0.30%via OSV
CVE-2026-34531Medium· 6.5
6mo ago

Flask-HTTPAuth invokes token verification callback when missing or empty token was given by client

Flask-HTTPAuth invokes token verification callback when missing or empty token was given by client

▾ Sunlitflask-httpauth · flask-httpauthEPSS 0.48%via OSV
CVE-2026-34881Medium· 5.0
6mo ago

OpenStack Glance is affected by Server-Side Request Forgery (SSRF)

OpenStack Glance is affected by Server-Side Request Forgery (SSRF)

▾ Sunlitglance · glanceEPSS 0.44%via OSV
CVE-2025-64340Medium· 6.7
6mo ago

FastMCP has a Command Injection vulnerability - Gemini CLI

FastMCP has a Command Injection vulnerability - Gemini CLI

▾ Sunlitfastmcp · fastmcpEPSS 0.73%via OSV
CVEs tagged “pip” — page 71 · VulnSea